StoreFront

Cumulative Update 1 (CU1)

Release date: December 16, 2025

About this release

StoreFront (initial release)

If StoreFront has been onboarded to Citrix Analytics then Citrix recommends against installing this release. For more information, see Known issues.

Citrix Product Subscription Advantage Eligibility Dates

Citrix Workspace app for HTML5

This release includes Citrix Workspace app for HTML5 2511.

What’s new in 2507 LTSR CU1

Cumulative Update 1 (CU1) is the latest release of the StoreFront 2507 LTSR. See What’s new.

If you have onboarded your servers to Citrix Analytics then Citrix recommends that you do not install this release. For more information, see Known issues.

Starting with the CU1 release, when you sign in to StoreFront, you can see timely and relevant information about the launch status of Citrix Workspace app for HTML5. For more information, see Improved Virtual Apps and desktops launch experience.

Support for users with Entra ID identities (Preview)

Previously StoreFront required users to exist in Active Directory. With this release, if users authenticate using OIDC with Microsoft Entra ID at a Citrix Gateway, users with Entra ID can enumerate and launch Citrix DaaS resources that are assigned to their Entra ID identities. For users with hybrid identities, StoreFront also enumerates any resources that are assigned to their Active Directory identity.

It has the following limitations:

  • Users authenticating using SAML continue to be treated as having only Active Directory identities and cannot enumerate resources assigned to Entra ID identities.
  • Users must authenticate via a Citrix Gateway rather than directly to StoreFront.
  • If users are in a large number of Entra groups, you might experience high memory usage on the StoreFront server.
  • Citrix Virtual Apps and desktops sites are not supported. Resources in Citrix Virtual Apps and desktops sites may fail to enumerate.
  • Configuration is not available in the management console. Administrators must use PowerShell.
  • FAS is not supported on stores where users have Pure Entra ID identities.

For more information, see Entra ID authentication via OIDC.

Entra ID single sign-on to VDAs (Preview)

If users have authenticated using Entra ID then when they launch a resource hosted on an Entra joined VDA, they can single sign-on to Entra ID joined VDAs.

It has the following limitations:

  • This is only supported when authenticating via a Citrix Gateway, using a connection to Entra ID via OIDC rather than SAML.
  • This must be configured using PowerShell.
  • Configuration is not available in the management console. Administrators must use PowerShell.
  • FAS is not supported on stores where Entra ID SSO is enabled.

For more information, see Single sign-on to VDAs.

Fixed issues

StoreFront 2507 LTSR CU1 contains the following fixes:

  • StoreFront Favorites do not synchronize between StoreFront servers when NTLM authentication is disabled. [CVADHELP-26155]
  • Users encounter a Cannot start app error when they attempt to access certain applications through the internal StoreFront (SF) URL. [CVADHELP-29201]
  • StoreFront servers intermittently log events 4010 and 4011, which indicates XML health check failures to the Delivery Controllers (DDCs). This causes occasional enumeration failures for users. [CVADHELP-28016]
  • When you install the Citrix Web extension and disable the protocol handler, ICA files download instead of launching applications. This occurs because the system fails to detect Citrix Workspace app properly when the protocol handler is disabled. The fix now displays “Citrix Workspace app is successfully detected via the browser extension” and allows users to redo client detection when needed. [CVADHELP-29591]

Known issues

  • If StoreFront is onboarded to Citrix Analytics, you might find significantly increased CPU usage. [CVADHELP-31084]
Cumulative Update 1 (CU1)